GCP Professional Cloud Security Engineer Practice Question
Your organization runs a shared-services VPC (10.10.0.0/16) that reaches on-premises through Dedicated Interconnect and Cloud Router. A separate development project needs private access to the shared database subnets but must stay isolated from on-premises. Engineers propose adding VPC Network Peering between the development VPC and the shared-services VPC and relying on Cloud Router to advertise any required on-prem routes. Which statement about VPC Network Peering must you verify before approving this plan?
The two VPC networks must have non-overlapping primary and secondary RFC 1918 address ranges; otherwise the peering request will fail.
Routes learned from the on-premises Cloud Router are automatically propagated through the peering connection to the development VPC.
You must configure IPsec VPN tunnels between the two VPCs before VPC Network Peering can exchange traffic.
After peering, ingress firewall rules defined in the shared-services VPC automatically apply to instances in the development VPC.
For a VPC Network Peering connection to be created, the primary and any secondary IPv4 ranges of both VPC networks must be unique and non-overlapping. If overlaps exist, the peering request fails. In contrast, dynamic routes learned from on-premises via Cloud Router are not automatically shared with a peer (peering is non-transitive), firewall rules do not cross VPC boundaries, and no VPN tunnels are needed for peered networks to exchange private traffic.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
Why must primary and secondary IPv4 ranges in VPC Network Peering be non-overlapping?
Open an interactive chat with Bash
What does 'non-transitive' mean in the context of VPC Network Peering?
Open an interactive chat with Bash
Why are ingress firewall rules not automatically applied in peered VPCs?
Open an interactive chat with Bash
What are overlapping IP address ranges, and why do they cause VPC Peering requests to fail?
Open an interactive chat with Bash
Why doesn't dynamic routing with Cloud Router propagate to peer networks?
Open an interactive chat with Bash
How does VPC Network Peering handle firewall rules?
Open an interactive chat with Bash
GCP Professional Cloud Security Engineer
Securing communications and establishing boundary protection
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .